What AI Regulations Require You to Track in 2026

What AI Regulations Require You to Track in 2026

What AI Regulations Require You to Track in 2026

Category:

AI Governance

AI Regulation

Published date:

The short answer

Every framework asks for the same three.

  • A record of each AI system you run and what it is for.

  • Evidence of what it did, retained for at least six months.

  • An owner accountable for it.

The EU AI Act makes this binding for high-risk systems from December 2027, while NIST and ISO/IEC 42001 are still operating on a voluntary basis yet.

Legal position and dates sourced on 21 Aug 2026 from the Official Journal, NIST and ISO published materials. This is not legal advice. Consult counsel on how any of it applies to you.

Key takeaways

  • Three frameworks matter for most organisations: the EU AI Act, which is binding but scoped, plus NIST AI RMF and ISO/IEC 42001, which are voluntary.

  • Your first question to address is whether you are a provider or a deployer under the EU AI Act. Almost every enterprise buying AI tools is a deployer, which narrows the duties considerably.

  • 29 US states passed 109 AI laws in the first half of 2026. Roughly 73% of Americans want AI development slowed and heavily regulated.

  • AI norms vary based on the risk classification of systems, but rules are not set yet. The appliedAI Institute classified 628 German AI startups in July 2026 and found 25.4% high risk, against the European Commission's own estimate of 5 to 15%. A further 69 could not be classified either way.

  • The gap is not awareness; it is record maintenance. Schellman found 74% of enterprises believe they are audit-ready for AI while 27% actually are. Fewer than one in five hold a complete, actively maintained inventory of which AI systems reach customer data.

  • That's what Guickly is solving first. It gives you one view of every AI tool, model and agent in the company. You can't regulate what you can't see.

Which frameworks apply to you?

Start here rather than with a statute. Work down the left. Each yes takes you out to what it means for you.

Decision tree titled Which AI rules apply to you today. Five questions covering EU market scope, provider or deployer status under the EU AI Act, its Article 5 prohibitions, its Article 50 transparency duties and high risk classification, each branching to what applies and from when.

Two things fall out of that tree for most organisations. You are almost certainly a deployer rather than a provider, which narrows your duties considerably.

Check your own position

Our tree above gives you the shape. These tools give you the detail. All of them are free. Check any classification against the date table further down, because some published checkers still run on the old text of the Act, before the amendments explained further down.

Tool

Run by

What it does

AI Act Service Desk and Compliance Checker

European Commission, AI Office

Official interactive questionnaire on scope and classification, an official Act explorer and an implementation timeline.

EU AI Act Compliance Checker

Future of Life Institute

Granular on roles. Separates provider, deployer, importer, distributor, product manufacturer and authorised representative. Flags when Article 25 turns a deployer into a provider.

NIST AI RMF Playbook

NIST

Suggested actions against each function and subcategory, including inventory subcategory

ISO/IEC 42001

ISO

The certifiable AI management system standard

Article 50 transparency guide

Future of Life Institute

Plain reading of the transparency duties, which is the part that binds you today

One thing to expect from any of them. They return an indicative classification, not a legal opinion.

Classification is also harder than the official estimates suggest. The appliedAI Institute for Europe classified 628 German AI startups in July 2026, taking the highest-risk use case for each. Of the 559 it could place, 25.4% came out high risk. The European Commission's own 2021 impact assessment had estimated 5 to 15% of AI applications would be high risk. The study says plainly that this estimate "does not apply to German AI startups". A further 26.3% landed in transparency obligations, the tier that binds today.

The other number in that study is the useful one for you. 69 of the 628 could not be conclusively classified at all, even after a human reviewed each one. The answer depended on deployment context and technical detail the reviewers could not see. If your own team disagrees about a classification, that is the normal condition, not a sign of incompetence.

That study looks at startups building AI, so it measures provider side classification rather than your position as a deployer. It is cited here to highlight how often the answer is unclear, not as an assessment on your own risk class.

Are you a provider or a deployer?

This is where most vendor content goes wrong and it changes the answer completely.

A provider develops an AI system and places it on the market. A deployer uses one under its own authority. If you are an enterprise buying Copilot, ChatGPT Enterprise, Claude, or a vendor's underwriting model, you are a deployer. Most of the AI Act falls on providers.

Obligation

EU AI Act article

Falls on

Deferred?

Technical documentation, Annex IV

Art 11

Provider

Yes

System must log events automatically

Art 12

Provider (design duty)

Yes

Retain automatically generated logs, at least six months

Art 19

Provider

Yes

Use per instructions, human oversight, monitor operation

Art 26(1) to (5)

Deployer

Yes

Retain logs under your control, at least six months

Art 26(6)

Deployer

Yes

Inform workers and their representatives before use at work

Art 26(7)

Deployer

Yes

Register use in the EU database

Art 49(3)

Deployer, public authorities only

Unresolved

Fundamental rights impact assessment

Art 27

Deployer, public bodies, public service providers, credit scoring and life or health insurance

Yes

Post market monitoring plan

Art 72

Provider

Yes

Disclose that a person is interacting with AI

Art 50(1)

Provider

No, in force

Mark synthetic output in machine readable format

Art 50(2)

Provider

No, in force

Notify people exposed to emotion recognition or biometric categorisation

Art 50(3)

Deployer

No, in force

Disclose deep fakes and AI generated text published on matters of public interest

Art 50(4)

Deployer

No, in force

A developer needs to note that Article 25(1) turns you into a provider in three cases. You put your name or trademark on a high-risk system. You substantially modify one. Or you "modify the intended purpose of an AI system, including a general-purpose AI system" so that it becomes high risk.

Build an internal tool on a general purpose model, aim it at hiring or credit decisions and you inherit the full Article 16 provider stack.

What the three frameworks actually ask for

Three frameworks matter for most organisations. They differ on force. They converge almost completely on substance.

Framework

Applies to you if

Binding?

What it actually asks you to hold

When

EU AI Act

You place AI on the EU market, or your AI output is used in the EU

Yes, but scoped

Per system technical documentation, automatic event logs kept at least six months, an accountable deployer, transparency notices

Transparency now. High risk documentation and logging from 2 Dec 2027

NIST AI RMF 1.0

You want a recognised structure, or you sell to US federal or Texas buyers

No, voluntary

"Mechanisms are in place to inventory AI systems", resourced by risk priority (GOVERN 1.6)

Available now. Under revision

ISO/IEC 42001:2023

Your buyers ask for certification, or you need to answer their security review

No, but certifiable and contractually demanded

A defined and documented management system scope, per system technical documentation, event logs

Available now

Two details worth knowing rather than memorising. NIST is explicit that it is voluntary: "NIST has produced the AI RMF as a voluntary Framework." But Texas TRAIGA names substantial compliance with the NIST AI RMF as a safe harbour. That is how a voluntary framework picks up legal weight without becoming law.

On ISO, one caution. No Annex A control title contains the word inventory. Clause 4.3 requires the management system scope to be documented. The per system documentation and logging controls sit in Annex A. Those Annex A numbers are behind the ISO paywall, so verify them against a purchased copy before quoting them anywhere that matters. ISO 42001 is also where commercial pressure concentrates. Its supplier control puts your vendors in scope. That is how the question travels down a supply chain and lands in your procurement questionnaire.

When the obligations land

The dates below are the current legal position. Two of them moved this year, which is why a lot of published guidance is out of date.

The reason is the Digital Omnibus. An omnibus is one law that amends several existing laws at once. The EU uses them to make housekeeping changes without reopening each act separately. This one amended the AI Act. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. Its main effect was to push the high risk regime back. The new dates are fixed, with no trigger or condition attached.

Date

What applies under the EU AI Act

Status

1 Aug 2024

Regulation (EU) 2024/1689 enters into force

In force

2 Feb 2025

Prohibited practices (Art 5), AI literacy duty (Art 4)

In force

2 Aug 2025

General purpose AI model obligations, governance, enforceable penalties

In force

2 Aug 2026

Transparency obligations (Art 50)

In force

2 Dec 2026

New prohibitions on non consensual intimate imagery and CSAM. Marking deadline for synthetic content systems already on the market

Pending

2 Aug 2027

Member State regulatory sandboxes operational

Deferred from 2 Aug 2026

2 Dec 2027

High risk regime for standalone Annex III systems: risk management, technical documentation, logging, deployer duties

Deferred from 2 Aug 2026

2 Aug 2028

High risk regime for AI embedded in regulated products

Deferred from 2 Aug 2027

Sources: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744, Official Journal, 24 July 2026.

Three things the Omnibus also did, briefly. It softened the AI literacy duty to supporting staff literacy rather than guaranteeing a level. It added the new prohibitions above. And it moved the bias detection legal basis into a new provision covering all AI systems rather than only high risk ones.

On US state law, briefly. There is no federal AI statute. Colorado repealed and replaced its AI Act with the Automated Decision-Making Technology Act, effective 1 January 2027, which keeps a three year record retention duty for developers and deployers. Texas TRAIGA has been in force since 1 January 2026 and creates no inventory duty. Beyond that it is patchwork: 29 states passed 109 AI laws in the first half of 2026 alone.

What to keep in mind when you build this

This is the part no framework document tells you. It is where organisations lose the most time.

  1. Agree what counts as an AI system before you count anything. The EU AI Act definition is deliberately broad. It captures things teams do not think of as AI, including embedded features inside software you already bought.

  2. Classify per system, not per company. You will be a deployer for almost everything and a provider for a handful of internal builds. The handful is what carries the real exposure, so the question is not "what are we" but "which of these are we a provider for".

  3. Build a live record, not an audit snapshot. This is the most common failure and it is measurable. Schellman's 2026 State of AI Governance report found that 74% of enterprises believe they are audit ready for AI while only 27% actually are.
    Separate research finds fewer than one in five organisations hold a complete, actively maintained inventory of which AI systems can reach customer data. More than half have no systematic inventory of AI in production at all. A spreadsheet assembled for a board meeting is out of date within a quarter. AI adoption inside a company does not move at the speed of an audit cycle.

  4. Start retention before you need it. Log retention is not retrospective. A six month minimum starting in 2028 tells you nothing about 2027.

  5. Name a human owner for each system. Every framework here asks who is accountable.

  6. Know what you are not required to log. This one saves money and reduces the surface are. The EU AI Act does not ask you to log prompts. It does not ask you to log outputs. It does not ask you to record which employee used which tool.

  7. Size the exposure honestly. Penalties have been enforceable since August 2025. The tier covering deployer duties and transparency runs to €15 million or 3% of worldwide turnover, whichever is higher. Prohibited practices run to €35 million or 7%.

  8. Do not build it only for the regulator. Procurement asks before any authority does. It asks in a form you cannot defer. The same record answers a security questionnaire, an internal audit, a board question about AI spend and, later, a compliance file.

  9. Expect the scope to move under you. Agentic systems are the current example: 74% of organisations plan to adopt agentic AI within two years while only 21% have a mature governance model for AI agents. A record designed only around the tools you bought last year will not survive the ones arriving this year.

Is AI regulation loosening or tightening?

Read the Omnibus on its own and the answer looks like loosening. Read the room and it does not.

The deferral was fought. 133 civil society organisations and unions urged the Commission to halt the package, describing it as the biggest rollback of digital rights in EU history. European Digital Rights argued the AI file "delays key protections, weakens transparency and creates a dangerous precedent". The European Centre for Not for Profit Law published a line by line analysis calling it deregulation at the expense of fundamental rights. Whatever you make of those positions, they tell you the political settlement is not stable. Deferred dates get revisited.

The public is not asking for less. Polling through 2026 puts support for slow, heavily regulated AI development at roughly 73% of Americans. About six in ten are more worried that government will do too little than too much. Another 73% say businesses are not transparent enough about how they use AI. That is bipartisan. It is the ground politicians stand on.

Legislatures are still writing. 29 US states passed 109 AI laws in the first half of 2026. Colorado repealed and replaced its own AI Act rather than abandoning it. The replacement keeps a three year record retention duty. The pattern is not retreat. It is churn with a rising floor.

Three column comparison. Binding today lists Article 5 prohibitions, Article 4 AI literacy, GPAI duties, live penalties and Article 50 transparency. Deferred not cancelled lists the Annex III regime for December 2027 and Annex I for August 2028. Pressure arriving anyway lists 133 civil society bodies opposing the rollback, 109 US state AI laws, public polling and ISO 42001 in procurement.

The useful way to hold this: the legal floor is low today and rising on a published schedule, while the commercial floor is already higher than the legal one. Your next enterprise deal will ask about AI governance before any regulator does.

Why the record is worth building before the deadline

Two dates moved. Nothing about what will eventually be required moved with them. The schedule is now published years in advance, which is unusual and worth using.

The reason to start early is not diligence for its own sake. It is that a record started in 2027 describes 2027 and nothing before it. Retention is not retrospective, so evidence you did not capture cannot be produced later.

And the regulator is not the first to ask. A procurement questionnaire asks which AI systems touch customer data. An auditor asks who approved the model in the underwriting flow. A board asks what the company spends on AI and what it got back. Those questions arrive before December 2027, they are asked by people who can withhold a contract rather than issue a fine. None of them can be answered from an expense report.

Guickly is the measurement layer for enterprise AI: one view of every AI tool, model and agent, what each costs and whether it works.

FAQ

Does the EU AI Act require an AI inventory? Not in those words. No article of the EU AI Act uses the word inventory. What it does require is four things. Technical documentation per high risk system under Article 11. Automatic event logging under Article 12. Log retention under Articles 19 and 26(6). Registration in the EU database under Article 49. Those duties presuppose an inventory without mandating one and most of them are now deferred to 2 December 2027.

When do EU AI Act high risk obligations actually apply? 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved both dates. Anything published before then citing 2 August 2026 is out of date.

What are enterprises legally required to track today? Under the EU AI Act, the live duties are the transparency obligations in Article 50. They took effect on 2 August 2026. Two of them bind deployers. Article 50(3) says you must notify people exposed to emotion recognition or biometric categorisation. Article 50(4) says you must disclose deep fakes and AI generated text published in the public interest. The prohibitions in Article 5 and the AI literacy duty in Article 4 have applied since 2 February 2025.

Is NIST AI RMF or ISO 42001 legally required? Neither. NIST states the AI RMF is voluntary and that organisations will not be required to use it. ISO/IEC 42001 certification is voluntary too. Both acquire practical force through contracts, procurement questionnaires and statutory safe harbours and Texas TRAIGA names substantial compliance with the NIST AI RMF as one of its safe harbours.

Do EU AI Act obligations fall on the company using AI or the company that built it? Mostly on the provider that built and placed the system on the market. A deployer using someone else's system has a shorter list, principally Article 26. A deployer becomes a provider under Article 25(1) in three ways. By putting its own name on a high risk system. By substantially modifying one. Or by repurposing a general purpose system so that it becomes high risk.


Your AI transformation

starts with visibility.

See every AI tool. Track every dollar. Control every budget. Optimize every call. One platform, live in under an hour.

GUICKLY

The AI Transformation Platform

Guickly gives enterprises complete visibility and control over their AI transformation from adoption through optimization. Trusted by teams that are AI-first.

©2026 Guickly. All rights reserved.

Your AI transformation

starts with visibility.

See every AI tool. Track every dollar. Control every budget. Optimize every call. One platform, live in under an hour.

GUICKLY

The AI Transformation Platform

Guickly gives enterprises complete visibility and control over their AI transformation from adoption through optimization. Trusted by teams that are AI-first.

©2026 Guickly. All rights reserved.

Your AI transformation

starts with visibility.

See every AI tool. Track every dollar. Control every budget. Optimize every call. One platform, live in under an hour.

GUICKLY

The AI Transformation Platform

Guickly gives enterprises complete visibility and control over their AI transformation from adoption through optimization. Trusted by teams that are AI-first.

©2026 Guickly. All rights reserved.